Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 09-19-2010, 11:59 PM
a9713030 a9713030 is offline
 
Join Date: Jun 2009
Posts: 25
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default 3.8.4 & 3.8.5 Registration Vulnerability

Code:
=========================================================
vBulletin 3.8.4 & 3.8.5 Registration Bypass Vulnerability
=========================================================

   010101010101010101010101010101010101010101010101010101010  
   0                                                       0
   1  Iranian Datacoders Security Team 2010                1
   0                                                       0
   010101010101010101010101010101010101010101010101010101010
  
 
# Exploit Title: vBulletin 3.8.4 & 3.8.5 Around Registration Vulnerability
# Date: 29/08/2010                           
# Author: Immortal Boy                    
# Software Link: http://www.vbulletin.org
# Version: 3.8.4 & 3.8.5
# Google dork 1 : powered by vBulletin 3.8.4
# Google dork 2 : powered by vBulletin 3.8.5
# Platform / Tested on: Multiple
# Category: webapplications
# Code : N/A
  
#  BUG :  #########################################################################
  
1 > Go to Http://[localhost]/path/register.php
 
2 > Assume that forum admin user name is ADMIN
 
3 > Type this at User Name ===> ADMIN&#00
 
4 > &#00 is an ASCII Code
 
5 > And complete the other parameters
 
6 > Then click on Complete Registrarion
 
7 > Now you see that your user name like admin user name
  
After this time the private messages to the user (ADMIN) to sending see for you is sending .
 
 
#  Patch :  #######################################################################
 
1 > Go to AdminCP
 
2 > Click on vBulletin Options and choose vBulletin Options
 
3 > Choose Censorship Options
 
4 > type &# in Censored Words section
 
5 > Then click on Save
 
#############################################################################
 
Our Website : http://www.datacoders.ir
  
Special Thanks to : H-SK33PY , NEO , Sp|R|T , BigB4NG , 3r1ck , Dr.mute ,
 
hosinn , NIK , uones , mohammad_ir &  all iranian datacoders members
  
#############################################################################

how to fix the bug?
Reply With Quote
  #2  
Old 09-20-2010, 12:15 AM
JamesC70 JamesC70 is offline
 
Join Date: Jun 2007
Posts: 219
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

<a href="http://www.vbulletin.com/forum/showthread.php?361721-Security-flaw-found-in-vBulletin-versions-up-to-3.8.5-inclusive" target="_blank">http://www.vbulletin.com/forum/showt....8.5-inclusive</a>

A temporary fix is detailed in the above thread. Or you can move up to 3.8.6 PL1, which isn't affected by this.
Reply With Quote
  #3  
Old 09-20-2010, 09:08 AM
a9713030 a9713030 is offline
 
Join Date: Jun 2009
Posts: 25
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

a9713030, you do not have permission to access this page. This could be due to one of several reasons:

Your user account may not have sufficient privileges to access this page. Are you trying to edit someone else's post, access administrative features or some other privileged system?
If you are trying to post, the administrator may have disabled your account, or it may be awaiting activation.

--------------- Added [DATE]1284977866[/DATE] at [TIME]1284977866[/TIME] ---------------

can you post the content here?
Reply With Quote
  #4  
Old 09-20-2010, 01:31 PM
JamesC70 JamesC70 is offline
 
Join Date: Jun 2007
Posts: 219
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I linked to vbulletin.com, not vbulletin.org -- be sure you're using the correct login credentials. (As long as you have a legitimate vBulletin license, obtaining login credentials for vbulletin.com shouldn't be a problem.)

This website is for add-ons, modifications, etc that are NOT in the code vBulletin code. Technically, discussion about a perceived flaw in core vBulletin code would be off topic on vbulletin.org.... it belongs on vbulletin.com.
Reply With Quote
  #5  
Old 09-20-2010, 01:44 PM
a9713030 a9713030 is offline
 
Join Date: Jun 2009
Posts: 25
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

i have bought vbulletin liscence from forum.vbulletin-china.cn , but i have not vbulletin.com privileges so i can not see the content even i have register the vbulletin.com ,i have asked the customservice, it says that buy from vbulletin.org only can get privileges at vbulletin.org,

and they vbulletin.org is for united states and other country except europe,
vbulletin.com is for uk , and europe,
i really need to download something or add-ons on vbulletin.com, it refused me
,my username on vbulletin.com is aslo a9713030
i don;t know why a company have this terrible management, it don't think for custom,
Reply With Quote
  #6  
Old 09-20-2010, 01:52 PM
Lynne's Avatar
Lynne Lynne is offline
 
Join Date: Sep 2004
Location: California/Idaho
Posts: 41,180
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

You cannot 'buy' from vbulletin.org. You can 'buy' from vbulletin.com.

vbulletin.com doesn't have terrible management because you can't follow the instructions that say to use the *exact* same email to register with that you use for your license email.
Reply With Quote
  #7  
Old 09-20-2010, 02:38 PM
a9713030 a9713030 is offline
 
Join Date: Jun 2009
Posts: 25
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

i have bought from vbulletin-china.cn,
it can not open for a year,what happen, where you are?

where i use vBulletin C9299598A1B7 login to www.vbulletin.com it says

Something Went Wrong!
error_wrong_distributor_chinese
If you believe this should not have happened, please contact us.
it is nightmare !!!!
Reply With Quote
  #8  
Old 09-20-2010, 02:57 PM
JamesC70 JamesC70 is offline
 
Join Date: Jun 2007
Posts: 219
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by a9713030 View Post
i have bought from vbulletin-china.cn,
it can not open for a year,what happen, where you are?

where i use vBulletin C9299598A1B7 login to www.vbulletin.com it says

Something Went Wrong!
error_wrong_distributor_chinese
If you believe this should not have happened, please contact us.
it is nightmare !!!!
Then click the "Contact Us" link where you see that message. This will route your complaint to the proper people at vBulletin.com.

The error message itself means that your license cannot be verified. This could be due to poor recordkeeping at vbulletin-china.cn, or because the license was revoked due to piracy. We can't help you on vbulletin.org with this, you need to clear things up with vbulletin.com.
Reply With Quote
  #9  
Old 09-20-2010, 03:09 PM
TNCclubman's Avatar
TNCclubman TNCclubman is offline
 
Join Date: Sep 2008
Posts: 690
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

you posted the solution on how to fix the bug yourself.

1 > Go to AdminCP

2 > Click on vBulletin Options and choose vBulletin Options

3 > Choose Censorship Options

4 > type &# in Censored Words section

5 > Then click on Save
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 12:01 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.08050 seconds
  • Memory Usage 2,243KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_code
  • (1)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (9)post_thanks_box
  • (9)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (9)post_thanks_postbit_info
  • (9)postbit
  • (9)postbit_onlinestatus
  • (9)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete